Skip to content
CAI
Software that uses CAICheck a score

NVIDIA/OpenShell

74.8

Strong · 29 September 2026

470.2k

lines of production code

Rust

primary language

2

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

OpenShell is a secure sandboxing platform that manages isolated execution environments for AI agents and workloads across diverse compute backends like Docker, Kubernetes, and VMs. It enforces strict network and filesystem policies through a formal verification prover and a dynamic policy advisor that learns from denied connections. The system provides a comprehensive CLI, TUI, and multi-language SDKs for programmatic control, alongside robust authentication and credential management infrastructure.

Features

Add Dockerfile for external Kubernetes gateway

A new Dockerfile has been added to build the external Kubernetes gateway container. This image packages the prebuilt gateway and Kubernetes driver binaries, configures environment variables for the Kubernetes compute driver and sandbox runtime, and exposes port 8080 for the gateway service.

e2e/docker · high confidence

Add GPU workload test images and manifest-driven validation

The e2e/gpu directory now includes Dockerfiles and scripts for three GPU workload images—smoke-pass, smoke-fail, and cuda-basic—along with a README detailing their contract and build process. These images are used by a new manifest-driven validation approach, where a local \workloads.yaml\ manifest defines the image, command, and expected outcome for each workload, allowing the e2e suite to run GPU tests against OpenShell sandboxes using explicit manifest entries rather than relying on external community image dependencies.

e2e/gpu · high confidence

Add Nix package definitions for VM runtime and build dependencies

New Nix package files have been added to support the VM runtime and its dependencies. The vm-runtime.nix package fetches and extracts platform-specific artifacts (libkrun, umoci) for x86\_64-linux, aarch64-linux, and aarch64-darwin, compressing them with zstd. The aws-lc.nix package configures the AWS-LC library with Rust bindings and specific target settings. The z3.nix package overrides the Z3 solver to disable Python bindings and shared library building.

nix/pkgs · high confidence

Add SBOM license resolution and CSV export tooling

New scripts have been added to the deploy/sbom directory to enhance Software Bill of Materials (SBOM) management. The \resolve\_licenses.py\ tool automatically detects missing or hash-based (sha256) license identifiers in CycloneDX JSON files and resolves them by querying public registries (crates.io, npm, PyPI) and applying a built-in map of known licenses for specific Go modules and system packages. Additionally, \sbom\_to\_csv.py\ provides a new capability to convert these CycloneDX JSON SBOMs into CSV format, extracting key component details like name, version, type, purl, and resolved licenses for easier downstream analysis.

deploy/sbom · high confidence

Add built-in Google Cloud and Vertex AI provider plugins

Users can now configure Google Cloud and Vertex AI as built-in inference providers. The new \google\_cloud.rs\ and \vertex.rs\ modules implement the \ProviderPlugin\ interface, automatically injecting necessary environment variables (such as project IDs, regions, and service account emails) into the sandbox environment while respecting existing values and skipping empty configurations. This enables seamless integration with Google Cloud services without manual environment setup.

crates/openshell-providers/src/providers · high confidence

A new \CustomFooter\ component has been added to the Fern documentation site, replacing the default footer with a branded NVIDIA footer. This component displays the NVIDIA logo (with light and dark mode variants), a "Built with Fern" badge, and standard legal links including Privacy Policy, Terms of Service, and Accessibility, ensuring the documentation footer matches NVIDIA's branding and legal requirements.

fern/components · high confidence

Add example supervisor middleware content guard

Introduces a new example supervisor middleware service that inspects HTTP request and response bodies as well as WebSocket text messages for case-sensitive literal terms. The service operates in redact mode (replacing matches with a configurable string, defaulting to \[FILTERED\]) or deny mode (blocking delivery with a 403 response). It is provided as a research preview with a smoke test script, a sample policy, and an upstream fixture to demonstrate the middleware integration.

examples/sandbox-policy-quickstart, examples/spiffe-token-grant-demo, examples/supervisor-middleware-content-guard · high confidence

Add local inference example for NVIDIA API Catalog

Added a new example in \examples/local-inference\ that demonstrates calling the NVIDIA API Catalog via its native OpenAI-compatible endpoint. The example includes a Python client (\inference.py\) supporting both streaming and non-streaming requests, a provider profile (\nvidia-inference.yaml\) defining endpoint credentials and network policies, and a sandbox policy (\sandbox-policy.yaml\) allowing PyPI access. This provides users with a reference implementation for configuring local inference workloads with explicit policy-based credential injection.

examples/local-inference · high confidence

Add multi-agent notepad demo

Introduces a new example in \examples/multi-agent-notepad\ that demonstrates running multiple Codex coding agents in parallel OpenShell sandboxes, using a GitHub repository as a durable, concurrent shared notepad. The demo includes orchestration scripts (\demo.sh\, \runner.sh\), network and filesystem policies (\policy.template.yaml\), and agent prompts to illustrate a map/reduce pattern where worker agents write individual notes and a synthesis agent produces a summary, highlighting features like provider-backed credentials and scoped network policies.

examples/multi-agent-notepad · high confidence

Added snap-gateway-repro.sh script for testing OpenShell snap lifecycle

A new bash script, snap-gateway-repro.sh, has been added to the test-guest scripts directory to reproduce and verify the OpenShell snap installation lifecycle. This tool allows users to test install.sh behavior in three specific modes: system-docker (verifying it does not install the Docker snap when a daemon is present), missing-docker (verifying it fails safely when Docker is absent), and docker-snap (verifying it rejects installation when the Docker snap is installed). The script supports repeated attempts to test idempotent refreshes and provides detailed diagnostics on failure, including snap services, connections, journal logs, and gateway logs.

nix/test-guest/scripts · high confidence

Custom kernel configuration for OpenShell VM sandboxes

A new kernel configuration fragment (openshell.kconfig) is introduced to tailor the VM kernel for capability-free sandboxes. This configuration enables ext4 root disk support, cgroups for resource limits, and enforces security via Landlock, seccomp, and other LSMs, while disabling heavy hardening features like init-on-free to maintain performance.

crates/openshell-driver-vm/runtime/kernel · high confidence

Docker driver now enforces the shared authenticated boundary protocol

The Docker compute driver has been refactored to implement the new isolation backend, replacing the previous standalone model with a shared authenticated boundary. This change introduces strict outer-fence guarantees—such as default-deny egress and controller-loss fail-closed behavior—by binding container placement, protected sockets, and immutable OCI resource claims (container ID, image identity, and GPU claims) to a unified boundary configuration. Users benefit from stronger security isolation where sandbox network egress is strictly controlled and identity is cryptographically verified against the gateway, while the driver now exposes its capabilities and lifecycle through the standardized \openshell-isolation-interface\ contract.

crates/openshell-driver-docker/src · high confidence

Executable identity resolution for Linux isolation backends

The new \openshell-binary-identity\ crate provides shared executable-identity resolution for RFC 0012 isolation backends on Linux. It resolves the identity of a process and its bounded ancestors by opening and hashing their \/proc/\<pid\>/exe\ objects, returning path-and-digest evidence along with diagnostic command-line paths. The resolver supports two scopes: a PID namespace (finding the init process) or a trusted process-tree root, and fails entirely if any executable cannot be opened, hashed, or validated.

crates/openshell-binary-identity · high confidence

Go SDK v1 introduces comprehensive authentication, client, and edge-proxy support

The Go SDK v1 now provides a complete client library for interacting with OpenShell gateways, featuring a unified \Client\ that exposes sub-clients for sandboxes, providers, exec, files, and more. Authentication is handled via pluggable \AuthProvider\ implementations, including static tokens, no-auth, and automatic OAuth2 token refresh with single-flight deduplication and exponential backoff. Users can also wrap any auth provider with extra headers for edge proxies, with a built-in \CloudflareAccess\ helper and a \TunnelProxy\ for bridging gRPC over WebSockets through HTTP/1.1-only edge proxies.

sdk/go/openshell · high confidence

Initial public API and internal contract definitions

The \proto\ directory now contains the authoritative source for OpenShell's gRPC contracts, establishing the public API (\openshell.proto\) and internal driver/interceptor contracts. This introduces the \OpenShell\ service with workspace-scoped resource management (sandboxes, templates, providers), a \ComputeDriver\ service for platform-agnostic sandbox lifecycle and capability negotiation, and a \CredentialDriver\ service for secure secret storage and resolution. The schema defines a \WorkspaceSelector\ for explicit workspace scoping, \ObjectMeta\ for consistent resource metadata, and a \SandboxPolicy\ supporting L7 protocol-aware network inspection (REST, GraphQL, WebSocket, MCP) with middleware injection. Additionally, \GatewayInterceptor\ and \SupervisorMiddleware\ services enable external governance and request/response mutation, while the legacy \navigator.proto\ has been removed.

proto · high confidence

Initial release of the Go SDK sandbox v1 protocol buffer definitions

This change introduces the generated Go code for the sandbox v1 API (\sdk/go/proto/sandboxv1/sandbox.pb.go\), establishing the foundational types and enums for the Go SDK. It defines core network configuration models, including \NetworkTlsMode\ (with \SKIP\, \TERMINATE\, and \PASSTHROUGH\ options), \NetworkEnforcementMode\ (supporting \ENFORCE\ and \AUDIT\ behaviors), and \NetworkAccessPreset\ (ranging from \READ\_ONLY\ to \FULL\ access). This file serves as the client-side type definition layer for interacting with sandbox network policies.

sdk/go/proto/sandboxv1 · high confidence

Initial release of the OpenShell TUI application

Introduces the OpenShell terminal user interface, providing a dashboard for managing gateways, providers, and sandboxes. The application features a splash screen, theme support (auto-detect, dark, and light modes), and interactive panels for viewing logs, editing global and sandbox settings, and managing provider configurations. It includes clipboard integration via OSC 52, keyboard navigation, and real-time log streaming from gateway and sandbox sources.

crates/openshell-tui/src · high confidence

Initial repository scaffolding and compliance setup

The repository has been initialized with foundational configuration and compliance files. This includes a \.dockerignore\ to exclude build artifacts, a \.env.example\ for local gateway configuration, and a \.markdownlint-cli2.jsonc\ to standardize documentation formatting. Compliance is established with Apache 2.0 licensing, a Developer Certificate of Origin (DCO), a Code of Conduct, and a Security policy. Additionally, a \.packit.yaml\ file is added to enable RPM builds via Fedora COPR, and a \.trivyignore.yaml\ is configured to manage security scan exceptions for Kubernetes manifests.

(repo-wide) · high confidence

Introduce @nvidia/openshell-sdk TypeScript client

The new \@nvidia/openshell-sdk\ package provides idiomatic TypeScript bindings for the OpenShell gateway, generated from protobuf definitions. It supports sandbox lifecycle management (create, delete, exec, streaming, and interactive sessions), port forwarding, and SSH sessions. Authentication is handled via static OIDC tokens or a renewable client-credentials provider that automatically discovers the issuer, validates the response, and handles token renewal. The SDK also includes a structured error taxonomy that decodes gateway error details and a typed deletion outcome system to clearly distinguish between completed, accepted, and missing-target states.

sdk/typescript · high confidence

Introduce Debian package for OpenShell with user-scoped gateway service

Users can now install OpenShell via a Debian package that includes the CLI, gateway daemon, policy prover, and VM compute driver helper. The package installs a user-scoped systemd unit for the gateway, which requires the user to manually enable and start it using \systemctl --user enable --now openshell-gateway\. The post-install script ensures that existing systemd user managers detect the new unit file without requiring a session restart.

deploy/deb · high confidence

Introduce Gator Gate Agent for automated PR review and monitoring

Adds a new manifest-driven Gator agent that runs a headless sandbox to validate and monitor OpenShell GitHub issues and pull requests. The agent uses a custom Dockerfile to provision a sandbox with Node.js 22, GitHub CLI, and the Codex harness, enforcing strict filesystem and process policies via a provided policy.yaml. It introduces a suite of shell utilities to manage the review lifecycle: a \gh\ wrapper that prevents duplicate review dispositions and enforces versioned payloads, a \review-feedback-ledger\ to aggregate and scope review threads, a \validate-review-findings\ tool to normalize security findings and blockers, and a \resolve-gator-review-threads\ script to automatically close Gator-owned threads when findings are fixed. The agent is configured via \agent.yaml\ to run in watch mode, polling PRs and coordinating with a principal-engineer-reviewer sub-agent.

scripts/agents/gator · high confidence

Introduce Go SDK for OpenShell v1 API

This change adds the initial Go SDK foundation for the OpenShell v1 API, providing the generated protobuf types and gRPC client stubs necessary to interact with the gateway. The new \openshellv1\ package exposes the complete public API surface, including methods for managing sandbox lifecycles (create, start, stop, delete), handling provider attachments and credentials, executing commands, and managing workspaces and policies. Users can now programmatically control OpenShell resources using the standard Go gRPC client interface.

sdk/go/proto/openshellv1 · high confidence

Introduce Go SDK foundation with typed workspace selectors and authorization rules

This change adds the initial Go SDK foundation in the \sdk/go/proto\ directory, introducing generated protobuf types that define core API capabilities. Specifically, it adds \WorkspaceSelector\ and \WorkspacePhase\ types to \datamodelv1\, enabling typed selection of single or all workspaces for API requests. It also introduces \AuthorizationRule\ and extension fields in \optionsv1\, which define per-method authorization metadata (including auth mode, roles, and scopes) consumed by the gateway's descriptor-pool-based auth table. These types form the structural basis for the Go SDK's sandbox client and API interactions.

sdk/go/proto/datamodelv1 · high confidence

Introduce OpenShell Docker build infrastructure and gateway configuration

This change adds the foundational Docker build system for OpenShell, introducing dedicated Dockerfiles for the CI runner, gateway, CLI, sandbox, supervisor, and macOS cross-compilation targets. It establishes a multi-stage build strategy using distroless base images for production components and osxcross for macOS binaries, alongside a shared cross-build helper script to streamline Rust compilation across architectures. The entry also includes the initial docker-compose setup and gateway configuration (gateway.toml) for local development, enabling users to run the gateway and manage sandboxed agents via Docker.

deploy/docker · high confidence

Introduce OpenShell Python SDK with typed gateway errors and schema v2 parity tests

This change introduces the \openshell\ Python package, providing a new SDK for agent execution and sandbox management. It exports core client classes (SandboxClient, WorkspaceClient) and typed error handling (GatewayError) that decodes gRPC status details like field violations and retry delays. The package also includes a comprehensive test suite validating the new gateway configuration schema v2, ensuring capability parity and correct migration paths for existing deployments.

python/openshell · high confidence

Introduce OpenShell-to-MXC policy mapping module

The \policy\_map\ module in the MXC driver now maps OpenShell sandbox policies to Microsoft MXC \ContainerConfig\ files. It provides two mapping strategies: a coarse standalone mapper that flattens network policies into host allowlists, and a governed-egress split that delegates network enforcement to an OpenShell CONNECT proxy while MXC handles filesystem and containment. The module generates structured loss reports and human-readable summaries to highlight semantic gaps, unsupported features, and backend-specific behaviors (such as filesystem default-deny differences or network proxy limitations) between OpenShell and MXC.

_crates/openshell-driver-mxc/src/policy\map · high confidence

Introduce Podman compute driver for sandbox workloads

This change adds the \openshell-driver-podman\ crate, implementing the compute driver interface for managing sandbox containers via the Podman REST API. It introduces support for creating, starting, and stopping sandboxes, with configuration for user namespaces, SELinux labels, and corporate HTTPS proxy egress. The driver also handles sandbox authentication via JWT secrets, exposes OpenTelemetry tracing, and includes platform-specific socket discovery for both native Linux and macOS Podman Machine environments.

crates/openshell-driver-podman/src · high confidence

Introduce RFC 0012 Isolation Backend contract and Linux primitives

The \openshell-isolation-interface\ crate now provides the object-safe, runtime-selectable contract for sandbox backends (RFC 0012), allowing the supervisor to drive isolation boundaries through a fixed lifecycle (attach, confirm, ready, running) without branching on specific implementations. This includes Linux-specific primitives for capability-free sandboxing, such as prebuilt seccomp self-protection filters for workload children, race-resistant Landlock root allow-lists, bounded socket registries for seccomp virtualization, and strict \/proc\-based socket identity helpers.

crates/openshell-isolation-interface · high confidence

Introduce RFC 0012 OpenShell Sandbox Protocol backend

The sandbox backend now implements the RFC 0012 isolation architecture, defining a versioned gRPC-based control protocol (\IsolationBoundary\) that multiplexes exec, relay, and DNS mediation over a single authenticated HTTP/2 connection. This change introduces the \OpenShellRuntimeBackend\ which handles supervisor-side lifecycle management, including strict credential epoch validation, same-epoch bearer renewal without dropping active streams, and TCP mediation recovery after boundary disconnects. It also adds a custom mediation framing layer for persistent DNS exchanges and enforces HTTP/2 flow-control limits to prevent stalled relay streams from starving control traffic.

crates/openshell-sandbox-backend · high confidence

Introduce VFIO PCIe passthrough lifecycle management

The \openshell-vfio\ crate now provides the core infrastructure for managing VFIO PCIe passthrough for OpenShell VM sandboxes. It includes device discovery (scanning sysfs for eligible devices, with specific NVIDIA GPU probing), binding devices to the \vfio-pci\ driver (handling driver overrides, ID registration, and companion device binding within IOMMU groups), and crash-recovery (reconciling stale bindings left over from previous crashes). The module exposes RAII guards to ensure devices are restored to their host drivers on cleanup and provides a testable abstraction over sysfs.

crates/openshell-vfio · high confidence

Introduce VM driver runtime configuration and documentation

The \openshell-driver-vm\ runtime location now includes a README and a \pins.env\ file that define the pinned versions for guest-side dependencies (umoci v0.6.0, libkrunfw v5.6.1, libkrun v1.19.4) and document the build and provenance workflows for the VM sandbox runtime.

crates/openshell-driver-vm/runtime · high confidence

Introduce VM isolation boundary provisioning module

Added a new \isolation\ module that implements the core logic for binding VM generations to supervisor boundaries. This change introduces \VmBoundarySpec\ and \VmBoundaryProvisioning\ structs to define immutable driver inputs and the resulting protected guest configuration. It includes logic to project outer fence evidence (enforcing default deny egress for VMs without network devices) and manage resource claims, including conditional GPU resource assertions. The module also provides unit tests to verify that provisioning correctly binds identical resource claims and that outer fence projections reject incomplete evidence.

crates/openshell-driver-vm/src/isolation · high confidence

Introduce built-in regex middleware and HTTP response pre-return inspection

The supervisor middleware now includes a first-party built-in implementation (openshell/regex) that applies fixed regular-expression replacements to HTTP request bodies and WebSocket text messages, and adds a new HTTP response pre-return interface that allows middleware to inspect and mutate response headers, trailers, and body streams before they are sent to the client.

crates/openshell-supervisor-middleware · high confidence

Introduce capability-free sandbox boundary with secure exec and lifecycle management

The sandbox runtime has been refactored into a capability-free boundary model that isolates the workload from the gateway and policy authority. This change introduces a new boundary server and exec implementation that manages workload lifecycle, including graceful freeze/resume during supervisor reconnection and strict termination on enforcement loss. It adds secure process execution via \LocalBoundaryExec\ with proper environment handling (including TLS CA injection and shell detection), and implements a cancellation mechanism for blocking network accepts using \SIGUSR2\ to prevent resource leaks. Additionally, it introduces anonymous activity and denial aggregators to periodically flush network usage and policy violation summaries to the gateway, improving observability without exposing sensitive details.

crates/openshell-sandbox · high confidence

Introduce declarative provider profiles for credential discovery

The \openshell-providers\ crate now supports declarative provider profiles (YAML/JSON) that define credential requirements and discovery logic. Operators can import these profiles to configure providers, and the system automatically discovers credentials by scanning environment variables specified in the profile. This replaces ad-hoc configuration with a structured, profile-driven approach, including specific handling for providers like Google Vertex AI.

crates/openshell-providers/src · high confidence

Introduce disposable Linux VM test guest harness

Developers can now boot and configure disposable Linux VMs for testing OpenShell packages using Nix, QEMU, and Ansible. The new \nix/test-guest\ module supports Ubuntu 24.04/26.04, CentOS Stream 10, Fedora 44, and Rocky Linux 9, with configurations for Docker, rootful and rootless Podman, SELinux, and snapd. It provides a \test-guest\ app for interactive sessions and a \test-guest-cache\ app for managing prepared disk images via local storage or OCI registries, enabling reproducible, isolated testing environments.

nix/test-guest · high confidence

Introduce extension credential management and Kubernetes secrets driver

The server now includes a new \openshell-extension-core\ library that provides protocol-neutral primitives for extension mechanisms, including JWT-based bearer token rotation, identity/audience validation, and transport configuration (HTTPS/Unix sockets). This enables extensions to authenticate outbound requests with short-lived, refreshable credentials. Additionally, a new standalone \openshell-driver-kubernetes-secrets\ binary is introduced to act as a credential driver, binding to a Unix socket and using Kubernetes Secrets to store and serve credentials to the gateway.

crates/openshell-server · high confidence

Introduce formal policy prover with Z3-based containment and risk checking

The \openshell-prover\ crate adds a formal verification layer for OpenShell sandbox policies, using the Z3 SMT solver to model policy constraints and detect security risks. It provides a standalone containment API (\check\_within\_boundary\) that validates whether a candidate policy stays within an operator-defined boundary, checking process identities, Landlock compatibility, and filesystem access. Additionally, it performs reachability analysis to identify four specific risk categories: link-local reach, L7 bypass with credentials, credential reach expansion, and capability expansion. The prover relies on embedded binary and API capability registries (e.g., for \curl\, \git\, \GitHub API\) to understand binary behaviors and credential scopes, and supports an 'accepted risks' mechanism to filter known findings.

crates/openshell-prover · high confidence

Introduce gateway interceptor framework for request validation and modification

The new \openshell-gateway-interceptors\ crate provides a framework to intercept, validate, and modify gRPC requests at the gateway boundary. It supports three execution phases—ModifyOperation, Validate, and PostCommit—allowing interceptors to inspect and patch request bodies using JSON Patch operations before they reach handlers. The system enforces security by automatically omitting fields marked with the \openshell.options.v1.secret\ protobuf option and rejecting any patch paths that target these secrets. Interceptors are configured via \GatewayInterceptorConfig\ and can be authenticated using rotating bearer-token slots, with configurable timeouts and failure policies (FailClosed or FailOpen) to control behavior when interceptor services are unavailable.

crates/openshell-gateway-interceptors · high confidence

Introduce manifest-driven agent launcher with sandboxed runtime

Added a new generic launcher (\scripts/agents/run.sh\) and documentation (\README.md\) for running agents defined by YAML manifests. This system allows users to launch agents in isolated sandboxes where prompts, skills, and subagent definitions are baked into an immutable image payload. The launcher supports \once\ and \watch\ execution modes, handles provider credential injection, and manages the lifecycle of sandboxed harnesses (such as Codex) via a shared runtime supervisor.

scripts/agents · high confidence

Introduce modular gateway binary with selective compute driver support

The gateway is now built as a standalone binary (\openshell-gateway\) that acts as a composition boundary, allowing users to selectively enable specific compute drivers (such as Docker, Kubernetes, Podman, VM, or MXC) via Cargo features rather than linking all available drivers by default. This new structure decouples driver implementation from the gateway core, enabling smaller, targeted builds and clearer separation of concerns for first-party drivers like the VM driver, which now manages its own subprocess lifecycle and configuration (including corporate proxy support) within this crate.

crates/openshell-gateway · high confidence

Introduce native Windows MXC compute driver with ETW audit and governed egress

This change adds the \openshell-driver-mxc\ crate, providing a native Windows compute driver that manages sandboxes via Microsoft MXC (\wxc-exec\). The driver supports two backends: \IsolationSession\ for persistent, attachable sessions and \ProcessContainer\ (default) for one-shot AppContainer workloads. It introduces a real-time ETW-to-OCSF audit consumer that captures OS Sandboxing provider events and emits them into the gateway's tracing sink. Additionally, it implements Pattern-C governed egress, allowing MXC to handle filesystem grants while redirecting network traffic through a host CONNECT proxy. The driver is Windows-only and compiles to a stub on other platforms.

crates/openshell-driver-mxc/src · high confidence

Introduce sandbox VM init script for guest rootfs preparation

A new init script (openshell-vm-sandbox-init.sh) is added to handle the minimal initialization of sandbox VMs. It runs as PID 1 inside the guest, mounts essential filesystems, and prepares the rootfs by extracting local Docker or OCI images. The script also normalizes the sandbox user/group ownership within the guest image to ensure consistent permissions.

crates/openshell-driver-vm/scripts · high confidence

Introduce standalone libkrun VM compute driver

The VM compute driver now supports a standalone libkrun backend, enabling VM execution on macOS ARM64 and Linux (ARM64/x86\_64) without requiring QEMU. This change embeds the necessary libkrun and libkrunfw runtime libraries directly into the driver binary, automatically extracting and caching them at runtime. It also introduces a lifecycle extension framework that allows features like GPU passthrough and custom guest init drop-ins to be registered and activated via sandbox labels, while providing cross-platform process supervision to ensure VM helper processes are terminated if their parent dies.

crates/openshell-driver-vm/src · high confidence

Introduce standalone libkrun-backed VM compute driver

The \openshell-driver-vm\ crate is added as a new standalone compute driver that uses libkrun to boot microVMs. It embeds the necessary runtime artifacts (libkrun, guest sandbox, supervisor, and init scripts) and communicates with the gateway over a Unix-domain gRPC socket. The driver supports booting sandboxes from ext4 root disks with per-sandbox writable overlays, handles corporate HTTP proxy egress for image pulls, and exports traces via OTLP. It also includes a minimal guest init binary (\openshell-vm-init\) to prepare the network environment inside the VM.

crates/openshell-driver-vm · high confidence

Introduce standalone policy boundary checker CLI

The \openshell-prover\ command-line tool is now available to verify that a candidate policy remains within an operator-defined boundary. It accepts a candidate policy file and a boundary policy file, then checks containment across process, Landlock, and network (including destination IP) domains. The tool returns exit code 0 if the candidate is within the boundary, 1 if it exceeds it (providing a counterexample), and 2 or 3 for usage/internal errors or unsupported semantics. Output is available in text or JSON formats, with JSON including schema version, coverage domains, and detailed counterexample structures for process, Landlock, filesystem, and network violations.

crates/openshell-prover-cli · high confidence

Introduce the OpenShell SDK for programmatic gateway interaction

This change adds the \openshell-sdk\ crate, providing a shared async Rust client for OpenShell gateways. It exposes a high-level \OpenShellClient\ for sandbox lifecycle management (create, list, delete, exec, templates) and a raw gRPC escape hatch for other services. The SDK handles authentication via OIDC bearer tokens (with automatic refresh) and Cloudflare Access edge tokens (via a local WebSocket tunnel proxy), manages connection transport, and implements lazy pagination for list operations.

crates/openshell-sdk/src · high confidence

New 'Bring Your Own Container' example with port forwarding support

Added a new example demonstrating how to run a custom container image inside an OpenShell sandbox. The example includes a Python REST API, a Dockerfile, and documentation showing how to build the image and launch the sandbox using the \--from\ flag. It highlights the new port forwarding capability (\--forward 8080\) which allows users to access services running inside the sandbox from their local machine via an SSH tunnel.

examples/bring-your-own-container · high confidence

New CLI authentication and output formatting modules

The CLI now includes dedicated modules for browser-based Cloudflare Access authentication (auth.rs), OIDC authentication with Keycloak (oidc\_auth.rs), and edge-authenticated WebSocket tunneling for gRPC traffic (edge\_tunnel.rs). It also introduces a generic output formatting system (output.rs) that standardizes JSON, YAML, and table rendering across commands, and adds shell completion helpers (completers.rs) for gateways, sandboxes, providers, and workspaces.

crates/openshell-cli/src · high confidence

New Helm chart for namespace-scoped workspace prerequisites

A new \openshell-workspace\ Helm chart has been added to \deploy/helm/\ to manage namespace-scoped resources required for OpenShell Kubernetes sandboxes. This chart installs the ServiceAccount, Role, RoleBinding, and NetworkPolicy needed in each workspace namespace, allowing the gateway and workspace releases to be upgraded and removed independently. It supports shared-gateway deployments by binding to a shared gateway ServiceAccount and includes a NetworkPolicy that restricts sandbox SSH ingress to gateway pods. The chart also conditionally grants PVC metadata read permissions when caller driver config is enabled.

deploy/helm · high confidence

New MCP conformance end-to-end test harness

Added a new end-to-end test suite in \e2e/mcp-conformance\ that validates OpenShell's MCP proxy behavior against the upstream \modelcontextprotocol/conformance\ runner. The harness runs the untrusted upstream test runner in an isolated Docker container and bridges its requests to a host-side bridge service, which executes the actual MCP client inside an OpenShell-managed sandbox. This setup ensures that MCP traffic crosses the policy-enforced proxy, allowing verification of protocol version handling, JSON-RPC structure, and method parameter validation against pinned Tower profiles (0.22.2) and supported MCP revisions (2025-03-26 through 2026-07-28).

e2e/mcp-conformance · high confidence

New Policy Advisor CTF example for testing policy recommendations

Added a new capture-the-flag example in the policy-advisor directory that demonstrates the policy recommendation pipeline. The example includes a restrictive sandbox policy, a Python script with seven network gates, and documentation explaining how to use the TUI or CLI to approve mechanistic policy recommendations generated by the sandbox proxy.

examples/policy-advisor · high confidence

New SPIFFE-backed token exchange demo for Kubernetes and Podman

Added a new example demonstrating dynamic token exchange using SPIFFE JWT-SVIDs. The demo includes Kubernetes manifests (deploying a token issuer, alpha/beta services, and SPIRE helper) and a Podman variant for local testing, along with provider profiles and automation scripts to validate the gateway's token exchange grant type.

examples/spiffe-token-exchange-demo · high confidence

New TUI interface for managing providers, sandboxes, and global settings

The terminal UI now includes dedicated modals and dashboard views for creating and configuring providers and sandboxes, alongside a new Global Settings tab. Users can create providers through a multi-step wizard (select type, choose method, enter key) and create sandboxes by specifying name, image, command, providers, and ports. The dashboard displays gateways, providers, and sandboxes in a structured layout, while the sandbox detail view shows metadata, restart policies, and pending policy drafts. Global settings can be viewed, edited, and confirmed via overlay dialogs, with access control messages for non-admin users.

crates/openshell-tui/src/ui · high confidence

New VM runtime build and setup scripts

Added a suite of shell scripts in tasks/scripts/vm to manage the OpenShell VM driver runtime. This includes vm-setup.sh for one-time configuration (downloading pre-built libkrun/libkrunfw/umoci or building from source), build-libkrun.sh and build-libkrun-macos.sh for compiling the virtual machine monitor and kernel firmware, and compress-vm-runtime.sh for packaging these artifacts for embedding. Supporting utilities like download-kernel-runtime.sh, package-vm-runtime.sh, and \_lib.sh provide platform detection, dependency management, and compression helpers, while smoke-orphan-cleanup.sh validates that sandbox processes are correctly terminated during gateway shutdown.

tasks/scripts/vm · high confidence

New Vault and Database-backed credential storage drivers

Users can now persist credentials using two new driver implementations: a Vault-compatible HTTP API driver (openshell-driver-vault) and an encrypted database-backed driver (openshell-driver-db-credstore). The Vault driver supports Kubernetes and token-based authentication, configurable mount paths, KV version selection, and custom CA bundles, while the database driver encrypts credential envelopes using AES-256-GCM and stores them via a pluggable object store interface. Both drivers expose standard credential management operations (store, resolve, delete, list) and are designed to integrate with the existing credential provider framework.

crates/openshell-driver-vault · high confidence

New agent-driven policy management demo

Added an example demonstrating an end-to-end policy approval loop where a coding agent requests access changes. The demo shows how an agent inside a sandbox can propose narrow network rules when denied, how the gateway validates and holds proposals for human review (or auto-approves safe changes), and how the sandbox hot-reloads policies upon approval.

examples/agent-driven-policy-management · high confidence

New build, container, and documentation validation scripts

The tasks/scripts directory now includes a suite of new helper scripts to standardize the build and release workflow. A shared container-engine abstraction layer (container-engine.sh) detects and unifies Docker and Podman usage, enabling consistent image building and multi-arch publishing across environments. New scripts (docker-build-image.sh, docker-publish-multiarch.sh, docker-build-ci.sh) handle building and pushing gateway, sandbox, and supervisor images with support for prebuilt Rust binaries and buildx builders. Build reliability is improved with build-env.sh, which raises open-file limits on macOS for cross-compilation, and check-cargo-lockfiles.sh/ps1, which validates Rust lockfiles. Documentation integrity is enforced via check\_docs\_nav.py, which ensures Fern navigation slugs match file paths and titles. Additionally, codex\_security\_range.py automates the calculation of security scan ranges for pre-release candidates, and e2e-build-workload.sh/gpu-build-images.sh streamline the creation of end-to-end test artifacts.

tasks/scripts · high confidence

New conformance test runner infrastructure for OpenShell CLI

The \openshell-conformance\ crate now provides a reusable framework for verifying OpenShell CLI behavior against a suite of portable scenarios. This includes a process execution boundary (\ProcessCli\) that runs the CLI binary with configurable timeouts and environment variables, and a scenario runner that manages test execution, result collection, and diagnostic reporting. The crate bundles specific conformance scenarios such as smoke tests, sandbox lifecycle, file transfer, and policy proposals, allowing users to verify CLI correctness across different environments.

crates/openshell-conformance/src · high confidence

New core infrastructure for authentication, network activity tracking, and configuration defaults

The \openshell-core\ crate now includes foundational modules that support gateway and sandbox operations. A new \auth\ module provides an \EdgeAuthInterceptor\ for gRPC requests, supporting both OIDC Bearer tokens and Cloudflare Access edge tokens. Network observability is enhanced with \activity.rs\ and \denial.rs\, which define shared event types (\ActivityEvent\ and \DenialEvent\) for tracking allowed/denied connections and policy violations across supervisor components. Configuration management is standardized in \config.rs\ with canonical default constants (e.g., ports, image repositories) and a new \PolicyValidationFailureMode\ to control gateway behavior when policy validation fails. Additionally, \container\_paths.rs\ and \driver\_mounts.rs\ establish reserved control paths and validation logic for bind mounts, ensuring workspace isolation and preventing collisions with OpenShell's internal state.

crates/openshell-core/src · high confidence

New developer tooling and compliance scripts

Added a suite of new scripts to support development workflows and open-source compliance: \baseline\_workflow\_metrics.py\ records GitHub Actions performance baselines; \docker-cleanup.sh\ safely prunes unused container resources; \generate\_third\_party\_notices.py\ and \update\_license\_headers.py\ automate SPDX license header management and third-party attribution generation; \keycloak-dev.sh\ and \keycloak-realm.json\ provide a local OIDC test environment; \junit-to-html.xsl\ converts test reports to HTML; \lint-mermaid.mjs\ validates Mermaid diagrams in documentation; \smoke-test-network-policy.sh\ tests sandbox network policies; and \test-release-tag.sh\ validates the release workflow.

scripts · high confidence

New e2e support utilities for capability probing, conformance, and schema-aware configuration

The e2e/support area now includes several new helper tools and scripts to improve test reliability and configuration management. A new C utility (capbset-probe.c) verifies the capability-bounding-set behavior inside rootless Podman containers, while musl-dns-probe.c tests DNS resolution and TCP connectivity for musl-based environments. A new conformance runner (conformance.sh) allows standalone CLI conformance suites to execute against a configured gateway. Additionally, the Podman gateway configuration logic has been updated to support schema v2, introducing new options like 'if\_not\_present' image pull policies and gateway-owned guest TLS, alongside a Python script (debian-package-manifest.py) to parse installed package metadata without invoking container tools.

e2e/support · high confidence

New example demonstrating private IP routing via allowed\_ips policy

Added a new example in \examples/private-ip-routing\ that demonstrates how to use the \allowed\_ips\ sandbox policy field to allow sandboxed processes to reach services on private IP space (such as cluster-internal pods) that are normally blocked by the proxy's SSRF protection. The example includes a simple Python HTTP server, a Dockerfile to build it, and a README with step-by-step instructions for deploying the pod and creating a sandbox with a policy that whitelists specific CIDR ranges (e.g., \10.42.0.0/16\).

examples/private-ip-routing · high confidence

New example for running the Codex app server in an OpenShell sandbox

Adds a new example in \examples/codex-app-server\ that demonstrates how to build a Docker image with the Codex CLI, configure an OpenShell provider profile for OAuth token management, and launch a sandboxed Codex app server. The example includes a startup script that injects provider credentials into the Codex auth configuration and exposes the server's WebSocket endpoint through the local OpenShell gateway for host-side client connections.

examples/codex-app-server · high confidence

New governance interceptor example for sandbox and provider policy enforcement

This change introduces a standalone reference example (\examples/governance-interceptor\) that implements the \openshell.gateway\_interceptor.v1.GatewayInterceptor\ service. The example demonstrates how to vend provider profiles (GitHub and Slack) and make them the gateway's authoritative profile source, restricting provider creation to only those matching vended profiles. It enforces governance by signing sandbox policies with EdDSA JWTs, verifying signatures during sandbox creation, and blocking unsigned or modified policies. The interceptor also denies sandbox-authored policy proposals and unauthorized provider profile imports or deletions, providing a complete pattern for policy-first governance.

examples/governance-interceptor · high confidence

New per-gateway authentication and identity management infrastructure

The openshell-bootstrap crate now provides the core storage and generation logic for gateway authentication, enabling distinct auth modes (mTLS, OIDC, and edge proxy) and per-sandbox identity. It introduces secure, owner-only storage for edge tokens (with migration from legacy cf\_token), OIDC token bundles with expiry and login-prompt tracking, and mTLS PKI bundles with atomic file updates. Additionally, it generates Ed25519 JWT signing keys for minting per-sandbox identity tokens and manages gateway metadata (including OIDC issuer/client details and SSH host resolution) to support the CLI's endpoint resolution and authentication flows.

crates/openshell-bootstrap · high confidence

New sandbox network policy engine and host-side proxy infrastructure

The \openshell-supervisor-network\ crate now includes a comprehensive network policy engine and host-side proxy implementation. A new Rego-based policy file (\sandbox-policy.rego\) defines the logic for allowing or denying network connections based on endpoint and binary identity matching, providing detailed deny reasons for debugging. The Rust source introduces a \HostProxyConfig\ and \start\_host\_proxy\ function to manage a CONNECT proxy for compute drivers (such as Windows MXC) that do not run the Linux supervisor, handling TLS termination with an ephemeral CA. Binary identity is enforced via a \BinaryIdentityCache\ using SHA256 trust-on-first-use (TOFU) and a \ProcfsIdentityResolver\ to resolve executable identities from procfs on Linux. Additionally, new L7 inspection modules for GraphQL, JSON-RPC, and MCP protocols have been added to parse and inspect request bodies, while HTTP helpers handle chunked body normalization for inspection.

crates/openshell-supervisor-network · high confidence

New standalone CLI for running OpenShell conformance scenarios

A new \openshell-conformance\ CLI tool has been added to allow users to list and execute registered OpenShell CLI conformance scenarios. The tool supports filtering specific scenarios by name, specifying a custom OpenShell binary path, and outputting results in either text or JSON format, providing a dedicated interface for verifying conformance behavior.

crates/openshell-conformance-cli · high confidence

New supervisor-process crate for sandbox access-plane management

The \openshell-supervisor-process\ crate has been introduced to manage the supervisor's access plane, including an embedded SSH server, gateway session relay, and canonical process I/O multiplexing. It provides a \debug-rpc\ CLI for inspecting sandbox configuration and tokens, pushes sandbox logs to the server via gRPC, and installs static policy-advisor skills into the sandbox environment.

crates/openshell-supervisor-process/src · high confidence

New transparent TCP Redis example demonstrating policy-enforced network isolation

Added a new example in \examples/transparent-tcp-redis\ that demonstrates connecting a Docker-backed OpenShell sandbox to a Redis instance using native TCP instead of an HTTP forward proxy. The example includes a demo script, a Python client, and a policy configuration that authorizes specific hostnames and ports while blocking unapproved hosts, wrong ports, and direct IP connections via policy DNS and transparent TCP mapping.

examples/transparent-tcp-redis · high confidence

Supervisor introduces activity and denial aggregation with endpoint status reporting

The supervisor now collects and aggregates network activity and proxy denial events, flushing periodic summaries to the gateway for policy analysis and visibility. It also reports the last observed network result for configured external tool endpoints, coalescing observations and retrying with session-bound sequences to ensure consistent, idempotent reporting. Additionally, the supervisor can generate draft network policy rules from denial summaries to help users understand and resolve blocked connections.

crates/openshell-supervisor · high confidence

Vendored OCSF v1.7.0 schemas for offline validation

The \openshell-ocsf\ crate now includes vendored Open Cybersecurity Schema Framework (OCSF) v1.7.0 schema definitions (classes, objects, and profiles) in \schemas/ocsf/v1.7.0/\. These files enable offline validation of event structures against the OCSF standard, ensuring that emitted events conform to the expected schema without requiring network access to the OCSF Schema Server.

crates/openshell-ocsf/src · high confidence

Windows MXC example suite for e2e testing and OCSF audit trails

The examples directory now includes a comprehensive set of Windows-specific artifacts for the MXC driver, including PowerShell orchestrators (run-mxc-e2e.ps1, run-ocsf-audit.ps1, probe-mxc-host.ps1) and configuration files (TOML/YAML). These enable end-to-end testing of filesystem policies (read-only, read-write, default-deny) and network policy rejection, as well as a dedicated audit trail example that captures Windows ETW events and maps them to the OCSF schema for durable JSONL logging.

crates/openshell-driver-mxc/examples · high confidence

Removals

Removal of Docker factory build infrastructure

The Docker-based factory build system has been removed. The \Dockerfile.factory\ file, which defined a multi-stage Python build environment for the supervisor container, has been deleted, along with the \mise.toml\ configuration that previously managed the \build:factory\ and \build:all\ Docker build tasks. Users can no longer build or utilize the factory Docker image through these specific files.

docker · high confidence

Removal of gRPC/HTTP multiplexed server implementation

The \navigator-server\ crate no longer includes the code for the gRPC service, HTTP health endpoints, protocol multiplexing, or TLS support. The files \grpc.rs\, \http.rs\, \multiplex.rs\, and \tls.rs\ have been deleted, removing the server's ability to listen on a TCP port and serve health checks or gRPC requests via the multiplexed architecture previously defined in \lib.rs\ and \main.rs\.

crates/navigator-server · high confidence

Removal of navigator-core configuration module

The \config.rs\ file and its associated \Config\ struct (including TLS and bind address settings) have been removed from the \navigator-core\ crate. This eliminates the shared configuration management previously exposed via \lib.rs\, meaning users can no longer rely on this central module for server connection or TLS setup parameters.

crates/navigator-core/src · high confidence

Removal of the legacy Navigator CLI

The \navigator-cli\ crate has been deleted, removing the standalone command-line interface that previously provided \health\ and \status\ commands for connecting to the Navigator server. Users will no longer be able to run the \navigator\ binary to check server health or view version and uptime information via this specific CLI tool.

crates/navigator-cli · high confidence

Removal of the legacy Navigator Python package

The legacy \python/navigator\ package, which previously provided the agent execution and management SDK (version 0.1.0), has been removed from the codebase. This deletion eliminates the associated module initialization and its unit tests, reflecting the project's transition away from the Navigator identity.

python/navigator · high confidence

Removal of the legacy Navigator Sandbox process isolation crate

The \navigator-sandbox\ crate, which previously provided a standalone CLI and library for spawning and monitoring sandboxed processes (including timeout handling, signal management, and process group isolation), has been completely removed. This eliminates the legacy process-level sandboxing mechanism in favor of the newer, more comprehensive sandboxing infrastructure (such as network namespaces, policy engines, and container-based isolation) that has been developed across the codebase.

crates/navigator-sandbox · high confidence

Architecture

Introduce standalone Kubernetes compute driver

The Kubernetes compute driver is now a standalone crate (\openshell-driver-kubernetes\) with its own configuration, gRPC service implementation, and resource provisioning logic. This change decouples the driver from the core server, allowing it to run as an independent process that exposes a \ComputeDriver\ RPC surface. Users benefit from improved modularity, clearer separation of concerns between the gateway and the runtime driver, and the ability to configure Kubernetes-specific settings (such as namespace modes, image pull policies, and network policies) independently.

crates/openshell-driver-kubernetes/src · high confidence

Behavioural changes

Automated git-derived versioning and centralized protobuf build configuration

The openshell-core crate now automatically derives the application version from git tags and commit history for local builds, following a 'guess-next-dev' convention that bumps the patch version for development builds (e.g., 0.0.4-dev.3+g2bf9969ab) while preserving exact stable or prerelease tags. Additionally, the crate's build script now centrally discovers and compiles all protobuf files from the proto directory, generating both Rust code and a binary FileDescriptorSet used by the server to enumerate RPCs at runtime, ensuring consistent protocol definitions across the gateway, sandbox, and router.

crates/openshell-core · high confidence

CLI command structure reorganized into modular subcommands

The CLI command implementation has been refactored to extract shared helpers into a new \common\ module and split command groups into dedicated modules (\gateway\, \provider\, \provider\_readiness\). This restructuring improves code maintainability and separation of concerns without changing user-facing functionality.

crates/openshell-cli/src/commands · high confidence

CLI wrapper script renamed from 'nav' to 'openshell' with optimized rebuild detection

The development wrapper script in scripts/bin has been renamed from 'nav' to 'openshell' to reflect the project rebranding. This new script introduces a fingerprint-based rebuild check that monitors specific crates (openshell-cli, openshell-core, openshell-prover, etc.) and configuration files for changes, skipping compilation if the source state is unchanged. It also respects the CARGO\_TARGET\_DIR environment variable and automatically locates the local Z3 library for the build process.

scripts/bin · high confidence

Canonical policy schema and provider-layer composition

The \openshell-policy\ crate now owns the canonical authored policy representation (YAML/JSON serde, bounded parsing, and validation) in a new \openshell-policy-schema\ dependency, while adapting it to the runtime protobuf model. This introduces a reserved \\provider\\*\ namespace for provider policy layers, allowing provider endpoints to be composed into the effective sandbox policy without overwriting user-authored rules. The change also adds strict validation for L7 endpoint semantics (including transport choices like explicit TCP and TLS skip) and endpoint ambiguity detection to ensure deterministic policy behavior when multiple endpoints overlap.

crates/openshell-policy · high confidence

Clarifies agent skills location and adds Claude Code-specific configuration directory

The project now explicitly documents that agent skills are canonical in \.agents/skills/\ and shared across all tools, while \.claude/\ is reserved for Claude Code-specific configuration. A new \.claude/\ directory has been added, containing a README that explains this separation, a symlink \skills\ pointing to the shared skills directory, and subdirectories for agent persona definitions and persistent memory files that are specific to the Claude Code runtime.

.claude · high confidence

Migrate documentation site to Fern

The documentation site has been migrated to Fern, introducing a new configuration structure (fern/docs.yml, fern/fern.config.json) and a custom NVIDIA theme with specific light and dark mode styling. This change establishes a versioned publishing workflow that supports immutable release snapshots, a mutable dev channel, and a mutable latest channel, along with automated redirect synchronization to ensure legacy URLs resolve correctly.

fern · high confidence

RPM deployment introduces schema v2 configuration with automatic migration and Podman defaults

The RPM package now ships with a new schema v2 configuration format (gateway.toml) that pins the compute driver to Podman and defaults the bind address to 127.0.0.1. To support existing users, the package includes a migration script that automatically upgrades legacy schema v1 configurations to v2 during installation or upgrade, preserving any user-edited settings. This change is accompanied by new documentation (CONFIGURATION.md, QUICKSTART.md, TROUBLESHOOTING.md) detailing the new setup process, TLS certificate generation, and troubleshooting steps for rootless Podman environments.

deploy/rpm · high confidence

Removal of custom protobuf build script

The custom build script (build.rs) that previously handled protobuf compilation using tonic-build and a bundled protoc has been removed. This change indicates that the crate no longer manages proto file generation at build time, likely shifting to a pre-generated source approach or relying on a different build mechanism.

crates/navigator-core · high confidence

Removal of generated protocol buffer module

The generated protocol buffer code module (\navigator.v1.rs\) has been removed from the \navigator-core\ crate. This eliminates the local re-export of the generated types and service definitions, indicating a shift in how these protocol definitions are managed or consumed within the application.

crates/navigator-core/src/proto · high confidence

Removed NetworkBinary.harness field with backward-compatible wire decoding

The \NetworkBinary.harness\ field has been removed from the sandbox policy protocol buffer schema. To ensure backward compatibility, the system now ignores this field when decoding legacy wire formats, allowing existing stored policies to be read without error. The field's tag (2) and name are reserved in the schema to prevent future reuse, and tests confirm that legacy payloads decode correctly while the removed field is effectively dropped during round-trip serialization.

crates/openshell-core/src/proto · high confidence

Unified Linux cross-compilation toolchains via Nix

The Nix build system now provides a unified, platform-specific toolchain for Linux cross-compilation. This change introduces a new \nix/toolchain\ module that automatically selects the appropriate compiler environment (glibc 2.28 or musl) based on the target platform, constructs a proper sysroot for glibc targets, and configures environment variables (CC, CXX, LINKER) to use the custom driver. Users benefit from consistent cross-compilation setups across different Linux architectures without manual configuration.

nix, nix/toolchain · high confidence

Fixes

Snap gateway security hardening and Docker connection recovery

The snap now enforces mTLS by default, replacing any existing gateway configuration that allows unauthenticated or plaintext access during installation and refresh. Additionally, a new hook ensures the gateway daemon restarts automatically after the Docker plug is connected, allowing driver auto-detection to function correctly even if the daemon started before Docker was available.

snap · high confidence

Test coverage

Add Nix-based test infrastructure for tmachine VMs; Add e2e/parity harness to validate schema v2 gateway compatibility; Added Ansible test roles for tmachine container runtime and OpenShell gateway fixtures; Added Windows-specific policy mapping and MXC integration tests; Added conformance and driver-specific test suites; Added end-to-end tests for OIDC authentication and authorization; Added integration tests for CLI colorization, help output, gateway registration, and structured output; Added integration tests for the OpenShell SDK client; Added tests for Keycloak provider refresh recovery; Added tests for OCSF event identity and JSON round-trip fidelity; Added tests for release versioning and wheel verification logic; Added tmachine test harness for VM-based integration testing; Migrate e2e test infrastructure from Bash to Rust; New E2E test infrastructure and harness scripts; New Rust-based E2E test suite for sandbox security and configuration; New end-to-end tests for agent-driven policy management; New portable conformance scenarios for file transfer, policy, lifecycle, and smoke tests; Python e2e test suite for sandbox security, policy, and exec admission.

Dependencies

OpenShell Rust workspace restructured with new crates and dependency updates

The Rust dependency manifests have been reorganized into a comprehensive workspace structure, introducing several new crates including \openshell-binary-identity\, \openshell-bootstrap\, \openshell-conformance\, \openshell-driver-db-credstore\, \openshell-driver-vault\, \openshell-extension-core\, \openshell-gateway-interceptors\, \openshell-ocsf\, \openshell-prover\, and \openshell-prover-cli\. The update also incorporates specific library version bumps, such as \hyper-rustls\ to 0.27, \bollard\ to 0.20, \oci-client\ to 0.16, and \regorus\ to 0.9, while standardizing common dependencies like \serde\, \tokio\, and \tonic\ across the new and existing components.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Score

  • CAI 78 → 75 (-3.3)
  • Rubric changed (rubric-2026.09.9 → rubric-2026.09.17) — scores are not directly comparable.

Lenses

  • Code Health 74 → 74 (+0.5)
  • Architecture 95 → 95 (+0.3)
  • Maturity 85 → 85 (-0.0)
  • Readiness 87 → 72 (-14.8)
  • Security 82 → 76 (-5.9)
  • Event-Driven 80 → 80 (+0.1)
  • Event Sourcing 100 → 100 (+0.0)
  • Accessibility 80 → 80 (+0.0)
  • Performance 100 (new)

Resolved (267)

  • Change coupling: driver.rs ↔ validation.rs (crates/openshell-driver-kubernetes/src/driver.rs)
  • Change coupling: run.rs ↔ validation.rs (crates/openshell-cli/src/run.rs)
  • ComputeRuntime::start_persisted_sandboxes (cognitive 25) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::start_persisted_sandboxes (cyclomatic 16) (crates/openshell-server/src/compute/mod.rs)
  • Consequences/trade-offs are not visible before the scanner clips the body (durable rules and kernel relationships tables plus non-normative status) (rfc/0012-isolation-backend/topology-matrix.md)
  • Duplicated block (10 lines × 14) (crates/openshell-server/src/grpc/policy.rs)
  • Duplicated block (10 lines × 17) (crates/openshell-server/src/grpc/policy.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-cli/src/commands/provider.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-cli/src/commands/provider.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-driver-docker/src/lib.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-driver-kubernetes/src/driver.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-driver-vm/src/driver.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-sandbox/src/lib.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-server/src/grpc/auth_rpc.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-supervisor-network/src/l7/relay.rs)
  • Duplicated block (10 lines × 2) (crates/openshell-supervisor-process/src/run.rs)
  • Duplicated block (10 lines × 3) (crates/openshell-sandbox/src/lib.rs)
  • Duplicated block (10 lines × 3) (crates/openshell-supervisor-process/src/sandbox/linux/landlock.rs)
  • Duplicated block (10 lines × 8) (crates/openshell-cli/src/commands/provider.rs)
  • Duplicated block (10–11 lines × 2) (crates/openshell-driver-kubernetes/src/driver.rs)
  • …and 247 more

New (679)

  • ActivityAggregator::run (cognitive 28) (crates/openshell-supervisor/src/activity_aggregator.rs)
  • Ambiguous naming for distinct but related state. load_active_gateway likely returns the globally active gateway, while load_user_active_gateway returns the user-specific preference. The naming convention is inconsistent (load_ vs load_user_) and doesn't clearly distinguish scope (global vs user).
  • BoundaryRuntime::dispatch (cyclomatic 17) (crates/openshell-sandbox/src/boundary_server.rs)
  • ChainRunner::preflight_described_http_response (cognitive 62) (crates/openshell-supervisor-middleware/src/response/preflight.rs)
  • ChainRunner::preflight_described_http_response (cyclomatic 30) (crates/openshell-supervisor-middleware/src/response/preflight.rs)
  • Change coupling: policy.rs ↔ policy_local.rs (crates/openshell-server/src/grpc/policy.rs)
  • ClassTooLong: BoundaryClient (crates/openshell-sandbox-backend/src/runtime.rs)
  • ClassTooLong: HttpResponseSession (crates/openshell-supervisor-middleware/src/response.rs)
  • ClassTooLong: LayerApplier (crates/openshell-driver-vm/src/layer_applier.rs)
  • ClassTooLong: PodmanClient (crates/openshell-driver-podman/src/client.rs)
  • ComputeRuntime::create_sandbox_authenticated_with_guards (cognitive 20) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::create_sandbox_authenticated_with_guards (cyclomatic 16) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::reconcile_provisioning_deadlines (cognitive 20) (crates/openshell-server/src/compute/provisioning_deadline.rs)
  • ComputeRuntime::recover_persisted_lifecycle_transitions (cyclomatic 16) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::report_main_process_exit (cyclomatic 16) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::set_supervisor_session_state_from_snapshot (cognitive 26) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::set_supervisor_session_state_from_snapshot (cyclomatic 21) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::start_persisted_sandboxes_with_authentication (cognitive 50) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::start_persisted_sandboxes_with_authentication (cyclomatic 25) (crates/openshell-server/src/compute/mod.rs)
  • ComputeRuntime::start_sandbox_authenticated (cognitive 31) (crates/openshell-server/src/compute/mod.rs)
  • …and 659 more

Changes since last survey

  • 188 commits — 92 feature/other, 96 fixes

By area

  • crates/openshell-server — 17 commits
  • (root) — 14 commits
  • .github/workflows — 14 commits
  • deploy/helm — 12 commits
  • crates/openshell-supervisor-network — 10 commits
  • e2e/rust — 10 commits
  • tasks/scripts — 10 commits
  • sdk/go — 9 commits
  • crates/openshell-driver-vm — 6 commits
  • crates/openshell-cli — 4 commits
  • crates/openshell-sandbox — 4 commits
  • crates/openshell-sandbox-backend — 4 commits
  • .agents/skills — 3 commits
  • architecture/build.md — 3 commits
  • architecture/gateway.md — 3 commits
  • architecture/sandbox.md — 3 commits
  • crates/openshell-conformance — 3 commits
  • crates/openshell-driver-kubernetes — 3 commits
  • crates/openshell-driver-podman — 3 commits
  • crates/openshell-isolation-interface — 3 commits

Notable commits

  • fix: (Fix) ha sandbox resilience with k8s (#3644)
  • fix: fix(api): make WatchSandbox loss-aware and resumable (#3209)
  • fix: fix(auth): harden OIDC trust root retrieval (#3332)
  • fix: fix(auth): remove legacy sandbox JWT admission (#3562)
  • fix: fix(auth): skip renewal for non-expiring sandbox JWTs (#3686)
  • fix: fix(bootstrap): emit RFC 5280 extensions on generated gateway PKI (#3286)
  • fix: fix(ci)!: remove gateway callback listener dependency (#3365)
  • fix: fix(ci): keep snap canary sandbox name within limit (#3751)
  • fix: fix(ci): repair RFC 0012 post-merge checks (#3360)
  • fix: fix(ci): restore prebuilt Z3 on Windows (#3353)
  • fix: fix(ci): restore release tag push authentication (#3410)
  • fix: fix(ci): upstream Windows SDK validation support (#3327)
  • fix: fix(ci): use approved setup-oras revision (#3625)
  • fix: fix(ci): use renamed conformance suite in release dev (#3425)
  • fix: fix(cli): keep SSH forwards owned by spawned process (#3759)
  • fix: fix(cli): stream piped exec stdin beyond gRPC request limit (#3687)
  • fix: fix(container): use distroless Debian 13 for supervisor (#3393)
  • fix: fix(deps): refresh gateway Debian runtime image (#3350)
  • fix: fix(deps): update rustls past RUSTSEC-2026-0285 (#3484)
  • fix: fix(dev): extract Docker sandbox runtime from sandbox image (#3422)
  • …and 168 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

NVIDIA/OpenShell was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 29 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 9cb72baa2e61a1b5f12407e6e82da7fdba0aa722 — the exact code this score is about.
  • Scored under rubric-2026.09.17 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer preprod-705631bb727e.